US2019104130A1PendingUtilityA1

Apparatus and method for controlling network access

Assignee: SAMSUNG SDS CO LTDPriority: Sep 29, 2017Filed: Sep 18, 2018Published: Apr 4, 2019
Est. expirySep 29, 2037(~11.1 yrs left)· nominal 20-yr term from priority
H04L 63/0884H04L 63/083H04L 63/0892H04L 63/108H04L 63/102H04L 63/0209H04L 63/162
33
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An apparatus and method for controlling network access are provided. The apparatus for controlling network access includes an authentication information acquirer configured to receive user authentication information from one or more terminals, an extensible authentication protocol (EAP) host creator configured to create one or more virtual EAP hosts for the one or more terminals, each of the one or more virtual EAP hosts performing authentication in association with an authentication system through an EAP using the received user authentication information, an authenticator configured to relay messages exchanged for the authentication between each of the one or more EAP hosts and the authentication system through the EAP and an authentication, authorization, accounting (AAA) protocol and receive an authentication result and right control information from the authentication system, and a controller configured to control network access and right for each of the one or more terminals according to the received authentication result and right control information.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An apparatus for controlling network access, comprising:
 an authentication information acquirer configured to receive user authentication information from one or more terminals;   an extensible authentication protocol (EAP) host creator configured to create one or more virtual EAP hosts for the one or more terminals, each of the one or more virtual EAP hosts performing authentication in association with an authentication system through an EAP using the received user authentication information;   an authenticator configured to relay messages exchanged for the authentication between each of the one or more EAP hosts and the authentication system through the EAP and an authentication, authorization, accounting (AAA) protocol and receive an authentication result and right control information from the authentication system; and   a controller configured to control network access and right for each of the one or more terminals according to the received authentication result and right control information.   
     
     
         2 . The apparatus of  claim 1 , wherein the AAA protocol is one of Remote Authentication Dial-In User Service (RADIUS) protocol, DIAMETER protocol, Terminal Access Controller Access Control System (TACACS) protocol, and TACACS+ protocol. 
     
     
         3 . The apparatus of  claim 1 , wherein the authenticator encapsulates an EAP message received from each of the one or more virtual EAP hosts into an AAA protocol message, transmits the encapsulated message to the authentication system, decapsulates an AAA protocol message for each of the one or more virtual EAP hosts, which are received from the authentication system, into an EAP message and transmits the decapsulated message to each of the one or more virtual EAP hosts. 
     
     
         4 . The apparatus of  claim 1 , wherein the user authentication information includes a user ID and a password. 
     
     
         5 . The apparatus of  claim 1 , further comprising an additional information collector configured to collect additional information usable in determining a network access right for each of the one or more terminals,
 wherein the authenticator transmits the additional information to the authentication system.   
     
     
         6 . The apparatus of  claim 1 , wherein the EAP host creator sets a validity period for each of the one or more virtual EAP hosts. 
     
     
         7 . The apparatus of  claim 6 , wherein each of the one or more virtual EAP hosts performs re-authentication in association with the authentication system when the validity period has expired,
 the authenticator relays messages exchanged for the re-authentication between each of the one or more virtual EAP hosts and the authentication system through the EAP and the AAA protocol and receives a re-authentication result and right control information from the authentication system, and   the controller controls network access for each of the one or more terminals according to the re-authentication result and the right control information.   
     
     
         8 . A method of controlling network access, comprising:
 receiving user authentication information from one or more terminals;   creating one or more virtual extensible authentication protocol (EAP) hosts for the one or more terminals, each of the one or more virtual EAP hosts performing authentication in association with an authentication system through an EAP using the received user authentication information;   relaying messages exchanged for the authentication between each of the one or more EAP hosts and the authentication system through the EAP and an authentication, authorization, accounting (AAA) protocol;   receiving an authentication result and right control information from the authentication system; and   controlling network access and right for each of the one or more terminals according to the received authentication result and right control information.   
     
     
         9 . The method of  claim 8 , wherein the AAA protocol is one of Remote Authentication Dial-In User Service (RADIUS) protocol, DIAMETER protocol, Terminal Access Controller Access Control System (TACACS) protocol, and TACACS+ protocol. 
     
     
         10 . The method of  claim 8 , wherein the relaying comprises:
 encapsulating an EAP message received from each of the one or more virtual EAP hosts into an AAA protocol message;   transmitting the encapsulated message to the authentication system;   decapsulating an AAA protocol message for each of the one or more virtual EAP hosts, which are received from the authentication system, into an EAP message; and   transmitting the decapsulated message to each of the one or more virtual EAP hosts.   
     
     
         11 . The method of  claim 8 , wherein the user authentication information includes a user ID and a password. 
     
     
         12 . The method of  claim 8 , further comprising collecting additional information usable in determining a network access right for each of the one or more terminals,
 wherein the relaying comprises transmitting the additional information to the authentication system.   
     
     
         13 . The method of  claim 8 , wherein the creating of the one or more virtual EAP hosts comprises setting a validity period for each of the one or more virtual EAP hosts. 
     
     
         14 . The method of  claim 13 , further comprising:
 relaying messages exchanged for re-authentication between each of the one or more virtual EAP hosts and the authentication system through the EAP and the AAA protocol, when the validity period has expired;   receiving a re-authentication result and right control information from the authentication system; and   controlling network access for each of the one or more terminals according to the re-authentication result and the right control information.

Join the waitlist — get patent alerts

Track US2019104130A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.